logo

The long tail of Clop’s PTC hack is just beginning to emerge

ID: 0a4c6a14-bd78-556e-a7c6-141036843e96

STIX ID: report--0a4c6a14-bd78-556e-a7c6-141036843e96

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2026-08-19

Date Updated: 2026-08-20

Author: Matt Kapko

...
...

Clop exploited a critical zero-day (CVE-2026-12569) in PTC Windchill and FlexPLM to conduct a large-scale extortion campaign: the group deployed a custom Windchill web shell and toolkit to decrypt credentials, move laterally, exfiltrate data from dozens of organizations (including major enterprises), and send extortion demands while vendors and agencies published patches and indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.